Glossary
WORM Storage (Write Once, Read Many)
Storage that accepts a record once and then refuses every change or deletion until its retention period ends. WORM is how regulators expect audit trails, financial records and archived communications to be kept.
General definition
WORM Storage (Write Once, Read Many) began as a physical property of optical discs and tape. Today it is usually a policy on cloud object storage: an object is written, a retention period and mode are attached, and the storage service rejects overwrite and delete requests until that period passes. Amazon S3 Object Lock is the best-known implementation; Azure Blob immutable storage and Google Cloud Storage bucket lock and retention policies provide the same guarantee.
- Retention period: a fixed date or a duration (for example seven years) after which the object may be deleted
- Compliance mode: nobody, including the account root user, can shorten the period or delete the object before it expires
- Governance mode: protection applies by default, but specifically authorised users can override it, which is useful for testing and less strict use cases
- Legal hold: an open-ended lock, independent of the retention period, applied during litigation or investigation and removed explicitly
The standard driving much of this is SEC Rule 17a-4 in the United States, which requires broker-dealers to keep electronic records in a non-rewriteable, non-erasable format (an audit-trail alternative was added in 2022). FINRA Rule 4511 points at the same requirement, and bodies such as the CFTC and the FDA (21 CFR Part 11) have equivalents. HIPAA does not mandate WORM by name, but its integrity requirement and its six-year documentation retention are commonly met with it. In every case the point is the same: an audit log that the people it monitors could edit is not evidence.
WORM is not a backup. A backup policy protects against loss; WORM protects against alteration. Mature designs use both, and they store the immutable copy in a separate account or bucket from the production system so that a compromise of the application cannot reach the records. Versioning must be enabled for Object Lock, and encryption at rest still applies to locked objects.
In the Ethora ecosystem
Ethora’s compliance audit trail is built to be exported as immutable logs to Amazon S3. On a dedicated or self-hosted deployment the export target is a bucket in the customer’s own account, and the natural way to complete the setup is S3 Object Lock in compliance mode with a retention period that matches the regulation in play, so the exported records become WORM storage that neither Ethora nor the customer’s administrators can rewrite. The server-side message archive covers the conversations themselves, with configurable retention and per-user erasure where GDPR requires it.
This is the practical reason Ethora runs a compliance-archive model by default and keeps client-side end-to-end encryption as a per-app opt-in rather than the norm: a server that can see, archive and export messages is what makes immutable records possible for finance, insurance and healthcare customers. Retention windows are set per deployment, and the same exports can feed a SIEM or an eDiscovery process.